Jason Firch
1.2K posts

Jason Firch
@Jfirch
Search for knowledge. Know yourself. Then, and only then, can you help others to do the same.
Pennsylvania, USA เข้าร่วม Temmuz 2014
19 กำลังติดตาม949 ผู้ติดตาม
ทวีตที่ปักหมุด

@nayibbukele This assumes there is a free market. Consolidation will happen - it already has. The illusion of variety in grocery stores is one of many examples. The “losers” will fall while institutions fill the gap.
English

@pmarca When security becomes a compliance checkbox the only answer is that the vulnerabilities were an acceptable risk. Known or unknown.
English

@AISecHub Automating consulting services are great for checking the box and saving cash. Serious companies with regulations/compliance requirements won't be handing off something so important to AI. At least that's what I hear from decision makers I speak with.
English

Not generalists - specifically practitioners with multiple domains of expertise and high order system level thinking. I’ve worked with enough people in my career to know these people are rare.
Add the fact that you also need to learn how to use AI effectively and your actually pool of competition is very low.
English

@MeekMill I can help you secure it. AI models are dumb and easy to manipulate.
English

@MordyOberstein @SERanking @sengineland Proves that it doesn't work for brand new domains. Domains with established authority have different results. All this shows is that if you put out slop with no authority you won't be rewarded. Bit of an obvious conclusion, no?
English

Want to see what happens when you create AI content that you expect to rank at scale?
TLDR - 3-6 months in, your rankings will be in the gutter. They will not come back.
Great stuff from Bogdan Babiak (and @SERanking data team) on @sengineland!
searchengineland.com/ai-generated-c…

English

@illyism Type 1 =\= Type 2. 1 can be completed quickly. 2 requires you act on 1, have an observation period, and then complete an audit.
English

@DudeWhoInvests Makes all of the sense in the world as we face geopolitical instability. Gold is very liquid. Countries need liquidity for war🤷♂️
English

Makes LITERALLY ZERO sense. GOLD the hedge for geopolitical instability is crashing in the face of geopolitical instability. Can’t make this up.
The Kobeissi Letter@KobeissiLetter
BREAKING: Spot gold extends its selloff to -$400/oz on the day, now trading at $4,500/oz for the first time since February 2nd.
English

@NoAlphaLimits lol can’t cut rates. They won’t raise rates. They will lower rates. Weaponizing the dollar is easier at ZPIR. Also, they don’t care about a strong economy. They just want to make sure the right people are making the most money.
English

@KobeissiLetter A vulnerability scanner actually hurting crowdstrike’s valuations is laughable. Emotions are driving this more than anything. That, and some names need a scapegoat to justify to boards why their overvalued stocks are tanking.
English

@heyshrutimishra They didn’t kill cybersecurity. A scanner is a nothingberger in the full tech stack. Easy, low-hanging fruit. This won’t change budgets for the CISOs, IT VPs, or business owners I consult with.
English

Anthropic killed legal tech, cybersecurity, IT consulting, and now finance -- all in one month.
February 2026 is the month white-collar work died.
This is extinction-level automation.
Claude@claudeai
Introducing Cowork and plugin updates that help enterprises customize Claude for better collaboration with every team.
English

Anthropic just made the entire $15B application security market price in a question it can't answer.
Traditional AppSec tools from Snyk, Veracode, and Checkmarx charge per-developer licensing for static analysis. They find vulnerabilities. They generate reports. They flag code. Then a security engineer has to actually fix the problem, which is where 80% of the cost and 90% of the delay lives.
Look at the screenshot. Input sanitization audits. SSRF detection. Auth bypass tracing. RBAC enforcement reviews. These are the exact tasks that cost security consultants $300-500/hr and take weeks to schedule.
Claude Code Security doesn't generate a PDF full of findings for a human to triage. It writes the patches. That compresses the entire vulnerability lifecycle, discovery through remediation, into a single loop.
This tells you everything about where Anthropic sees the real margin in developer tools. Scanning is commoditized. Every CI/CD pipeline already runs some flavor of SAST/DAST. The bottleneck has always been fixing vulnerabilities fast enough to matter, and that bottleneck just disappeared.
The timing is worth noting too. Anthropic released this the same week enterprises are getting audited on SOC 2 and ISO 27001 compliance cycles. Security teams running 200+ open findings with a 90-day remediation SLA just got a tool that could clear that backlog in hours.
If you're building in AppSec right now, the competitive question changed. You're no longer selling "we find more bugs." You're competing against an AI that finds them and writes the patches in the same session.
Claude@claudeai
Introducing Claude Code Security, now in limited research preview. It scans codebases for vulnerabilities and suggests targeted software patches for human review, allowing teams to find and fix issues that traditional tools often miss. Learn more: anthropic.com/news/claude-co…
English

@elonmusk What prevents us from having all these things now without the intervention of AI? I'll wait.
English


@Prisc_Taravella @rustybrick Just popped into GSC and saw a bunch of updates - including search volume populating for keywords.
IMO the Search Console wars have begun. I checked out Bing Webmaster Tools after ignoring it for forever and it's incredible.
English

@rustybrick Is Google coming up with any updates to track AI searches visibility from the Search Console? 👀
English

ICYMI: Where are all those new Google Search Console features Google announced months ago? seroundtable.com/new-google-sea…



English

Also, agents can interact with your LLM, read all of the information, extract any data they want, and change any instructions / context docs if not locked down.
We've developed an AI readiness framework (100% free - no email needed) to address issues JUST like this: purplesec.us/resources/ai-s…
English

Beware of claudebot aka Moltbot. Giving LLMs full access to your computer and data doesn’t seem wise
Remember, most people just want to build cool things and make money.
They don’t understand the security implications. Just click “okay” and build me something cool just like it’s a terms of service agreement accept button.
English

@MasterNumber We can speak the truth, but it is not our responsibility to convince people. Take this perspective and things become easier.
English







